Heterogeneous SD-WAN-based Fusion Monitoring Method and System

By acquiring and analyzing monitoring data in a heterogeneous SD-WAN environment and establishing and correcting network topology and traffic topology structure models, the problem that traditional monitoring methods are difficult to integrate complex network monitoring parameters is solved, efficient network monitoring and resource optimization is achieved, and network stability and resource utilization efficiency are improved.

CN119109797BActive Publication Date: 2025-06-20SHENZHEN ISPISP TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411209427.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2025-06-20
Estimated Expiration
2044-08-30

AI Technical Summary

Technical Problem

In heterogeneous SD-WAN environment, traditional monitoring methods are difficult to integrate complex network monitoring parameters, resulting in problems such as management complexity and low resource allocation efficiency.

Method used

By obtaining monitoring data of heterogeneous SD-WAN environment, network component connection type analysis, traffic statistical feature extraction and traffic behavior pattern analysis, network topology model and traffic topology model are established, performance benchmarks are built, and abnormal behavior correction is performed on the model. Finally, network performance analysis report is generated through multi-dimensional data fusion, and resource allocation strategy is optimized based on the report.

Benefits of technology

Accurate monitoring and optimization of heterogeneous SD-WAN environments are realized, network stability and reliability are improved, resource management is enhanced, network resource utilization efficiency is improved, and network resource utilization problems are solved in traditional methods of complex configuration and low management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119109797B_ABST
    Figure CN119109797B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication transmission technologies, and in particular, to a heterogeneous SD-WAN fusion monitoring method and system. The method includes the following steps: obtaining heterogeneous SD-WAN monitoring data, analyzing the connection types of network components, and modeling a network topology structure model; extracting traffic statistical features, analyzing traffic behavior patterns, and marking the network topology model according to these patterns to generate a network traffic topology structure model; constructing a performance benchmark according to the traffic topology model and the monitoring data, correcting the network traffic topology model to identify abnormal behaviors, and forming a network traffic corrected topology structure model; extracting network component resource allocation features, performing data fusion in combination with the corrected model, and generating a network performance analysis report; optimizing the resource allocation strategy based on the analysis report and uploading it to the network management platform to execute the optimization task. The present invention can improve the overall network management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication transmission technologies, and particularly to a heterogeneous SD-WAN fusion monitoring method and system. Background Art

[0002] With the rapid development of information technology, the complexity and scale of enterprise networks have been continuously expanding. Traditional network architectures, especially traditional methods based on wide area networks (WANs), have gradually revealed their limitations. These limitations are mainly manifested as complex network management, low bandwidth utilization efficiency, unstable application performance, and difficulty in coping with diverse network requirements. Especially in the cross-regional and large-scale network connection requirements between enterprises, these problems become particularly prominent. To address these challenges, software-defined wide area network (SD-WAN) emerges as an innovative network technology. SD-WAN technology decouples network functions from physical hardware through virtualization technology, thus achieving centralized network management and dynamic optimization. SD-WAN can improve network reliability and performance through intelligent traffic management and optimization algorithms. However, due to the heterogeneity of the network environment (i.e., the diversity of network devices, connection types, transmission protocols, etc.), the implementation and management of SD-WAN become more complex. In practical applications, SD-WAN usually needs to be integrated with different types of network devices and technologies, including but not limited to traditional WAN devices, network devices from different manufacturers, and different types of connection media (such as MPLS, broadband Internet, LTE / 5G, etc.). The multiple network devices and protocols in the heterogeneous environment make it impossible for traditional monitoring methods to integrate complex network monitoring parameters and the configuration is difficult. Summary of the Invention

[0003] Based on this, it is necessary for the present invention to provide a heterogeneous SD-WAN fusion monitoring method and system to solve at least one of the above technical problems.

[0004] To achieve the above object, a heterogeneous SD-WAN fusion monitoring method includes the following steps:

[0005] Step S1: Obtain heterogeneous SD-WAN environment monitoring data, analyze the connection types of network components based on the heterogeneous SD-WAN environment monitoring data to obtain network component connection type data; model the heterogeneous SD-WAN network topology structure based on the network component connection type data to obtain a network topology structure model;

[0006] Step S2: Extract traffic statistical features from the monitoring data of the heterogeneous SD-WAN environment to obtain traffic statistical data, and perform traffic behavior pattern analysis based on the traffic statistical data to obtain traffic behavior pattern data; classify and label the traffic patterns of the network topology structure model according to the traffic behavior pattern data to obtain the network traffic topology structure model;

[0007] Step S3: Construct a performance benchmark based on the network traffic topology structure model and the monitoring data of the heterogeneous SD-WAN environment to obtain network performance benchmark data, and correct abnormal behaviors of the network traffic topology structure model according to the network performance benchmark data to obtain the network traffic corrected topology structure model;

[0008] Step S4: Extract network component resource allocation features from the monitoring data of the heterogeneous SD-WAN environment to obtain network component resource allocation data; perform multi-dimensional data fusion on the network component resource allocation data through the network traffic corrected topology structure model to obtain a network performance analysis report;

[0009] Step S5: Optimize the component resource allocation strategy for the network component resource allocation data based on the network performance analysis report to obtain an optimized network component resource allocation strategy, and upload it to the heterogeneous SD-WAN network management platform to execute the resource allocation optimization task.

[0010] By obtaining and analyzing the monitoring data of heterogeneous SD-WAN environments, the present invention can accurately understand the connection status of each network component and the network topology structure. This helps to clearly depict the actual operation of the network, thus laying a foundation for subsequent optimization and troubleshooting. The extraction of traffic statistical features and the analysis of traffic behavior patterns can reveal the actual usage and behavior patterns of network traffic. This is crucial for identifying traffic anomalies and performance bottlenecks, helping to establish a more accurate network traffic topology structure model to better understand and manage network traffic, solving the complex management problems brought about by the diversity of network devices and connection types, providing a clear network view through systematic topology modeling, and helping to better understand and manage the network structure. Constructing a network performance benchmark and correcting abnormal behaviors in the traffic topology structure model helps to identify and correct anomalies and potential problems in the network. This can ensure that the network performance is within the expected range, improving the overall stability and reliability of the network, solving the problem that traditional monitoring methods cannot monitor network performance in real time, and improving the accuracy of network fault detection and performance management through dynamic model correction. By extracting the resource allocation characteristics of network components and performing multi-dimensional data fusion, a detailed network performance analysis report can be generated, which not only integrates various monitoring data but also provides in-depth performance analysis, helping to identify optimization opportunities for resource allocation, thereby enhancing the accuracy of network resource management. This helps to deeply understand the resource usage situation, thus providing data support for subsequent resource optimization decisions. Optimizing the resource allocation strategy based on the performance analysis report can improve the utilization efficiency of network resources, reduce resource waste, and improve network performance. This makes the resource allocation in the SD-WAN environment more reasonable and efficient, ultimately enhancing the overall performance of the network, achieving intelligent optimization of resource allocation, and solving the problem of low management efficiency caused by complex configurations in traditional methods, improving the overall performance and management efficiency of the network through the implementation of optimization strategies. In summary, these steps effectively solve the problem of the large integration and configuration difficulty of complex network monitoring parameters in heterogeneous environments through systematic data analysis and model optimization.

[0011] Optionally, step S1 is specifically as follows:

[0012] Step S11: Obtain the monitoring data of the heterogeneous SD-WAN environment, and extract the connection characteristics of network components from the monitoring data of the heterogeneous SD-WAN environment to obtain network component connection data;

[0013] Step S12: Classify the connection types of network components for the network component connection data to obtain network component connection type data;

[0014] Step S13: Integrate the connection relationships of network center components according to the network component connection type data to obtain center component connection relationship data;

[0015] Step S14: Analyze the network communication topology structure based on the central component connection relationship data, so as to obtain the network topology structure model.

[0016] By obtaining the heterogeneous SD-WAN environment monitoring data and extracting the network component connection features, the present invention can understand in detail the connection methods and characteristics between different network components, which helps to identify potential bottlenecks or anomalies in the network and provides basic data for subsequent analysis. Classifying the network component connection data by type can distinguish different types of connections, help understand the specific roles and functions of each component in the network, and thus provide a basis for network optimization and fault troubleshooting. Integrating the central component connection relationships according to the network component connection type data can clarify the connection relationships of key components in the network, ensure the stability and efficiency of the core part of the network, and at the same time help to discover potential risks of the central node. Analyzing the network communication topology structure based on the central component connection relationship data can form a detailed topology structure model of the network, which helps to comprehensively understand the overall architecture of the network, optimize the network layout, and improve the network performance and reliability.

[0017] Optionally, step S12 is specifically as follows:

[0018] Step S121: Count the component connection frequencies of the network component connection data, so as to obtain the high-frequency connection component data and the low-frequency connection component data;

[0019] Step S122: Select the highest-frequency connection components according to the high-frequency connection component data, so as to obtain the network central component data;

[0020] Step S123: Count the central component connection frequencies of the high-frequency connection component data and the low-frequency connection component data according to the network central component data, so as to obtain the high-frequency central component connection component data and the low-frequency central component connection component data;

[0021] Step S124: Extract the component network connection delay characteristics from the network component connection data, so as to obtain the component network connection delay data;

[0022] Step S125: Classify the network delay components according to the component network connection delay data, so as to obtain the high-delay connection component data and the low-delay connection component data;

[0023] Step S126: Perform an intersection operation on the high-frequency central component connection component data and the low-delay connection component data to obtain the normal network connection component data; perform an intersection operation on the low-frequency central component connection component data and the high-delay connection component data to obtain the temporary network connection component data;

[0024] Step S127: Perform component connection merging based on the network center component data, normal network connection component data, and temporary network connection component data, so as to obtain network component connection type data.

[0025] Through frequency statistics, the present invention can identify the core components in the network, which are usually high-frequency connection components. This can better understand the key structure of the network. Knowing which components are frequently connected can help network administrators optimize resource allocation to ensure that these key components have sufficient bandwidth and processing power. Identifying low-frequency connection components can help find unused resources, thereby performing network optimization or adjustment. Selecting the connection components with the highest frequency can identify the central nodes in the network. These central nodes play a key role in the network, and analyzing them helps optimize the network structure. Understanding the network center components can help enhance the robustness of the system in network design and maintenance, reducing the impact of network failures on the overall performance. Through the statistics of the connection frequency of the central components, the connection pattern of the network can be analyzed more deeply, and the high-frequency and low-frequency central component connections can be identified. Understanding the central components with different connection frequencies can optimize the network layout, improve the network design, and enhance the overall network performance. Delay feature extraction can help identify the performance bottlenecks in the network, understand which component connections have higher delays, and then optimize these connections. By reducing network latency, the user experience can be improved, especially in applications that require real-time response, such as video conferencing and online games. The classified data can help network administrators prioritize the components with high latency and take measures to improve their performance. Through classification, network maintenance and optimization can be more targeted, reducing the impact on the entire network. Through intersection operation, the normal network connection components and temporary network connection components can be effectively distinguished, helping to understand different types of connections in the network. Identifying normal and temporary connection components helps optimize network scheduling and load balancing to ensure the efficient use of network resources. By merging different types of data, a comprehensive network connection view can be formed, helping to more comprehensively understand the network structure. Comprehensive data merging and analysis can provide strong support for network optimization and decision-making, improving the efficiency and effectiveness of network management.

[0026] Optionally, step S14 is specifically as follows:

[0027] Step S141: Extract component routing protocol features from the heterogeneous SD-WAN environment monitoring data, so as to obtain component routing protocol data;

[0028] Step S142: Perform component routing protocol clustering based on the component routing protocol data, so as to obtain routing protocol clustering component data;

[0029] Step S143: Perform network protocol topology structure analysis based on the routing protocol clustering component data and the network component connection data, so as to obtain a network protocol topology structure model;

[0030] Step S144: Analyze the virtual local area network (VLAN) logical topology structure based on the central component connection relationship data, so as to obtain a network logical topology structure model;

[0031] Step S145: Perform topology mapping on the network protocol topology structure model and the network logical topology structure model, so as to obtain a network topology structure model.

[0032] Through feature extraction of the monitoring data, the present invention can convert complex network monitoring data into useful component routing protocol data, which is convenient for further analysis and processing. Identifying and extracting the features of routing protocols helps to understand the behaviors and characteristics of different protocols in the network, thus laying a foundation for subsequent analysis and optimization. By analyzing specific routing protocol features, potential network performance problems or optimization points can be discovered, improving the overall network efficiency and stability. Clustering can group routing protocols with similar features into one category, thus simplifying and organizing the data and facilitating pattern recognition and analysis. Through cluster analysis, the commonalities and differences of different protocols in the network can be identified, and the interaction patterns of different components in the network can be understood, which helps to optimize the network configuration. The clustering results can be used to optimize network management and monitoring strategies to ensure the efficient operation and coordination of network components. Through topology structure analysis, the connection relationships and data flow conditions of each component in the network can be comprehensively understood, revealing the overall structure of the network. Understanding the topology structure of network protocols helps in network design optimization, improving network performance and fault tolerance. The network topology structure model can help quickly locate and solve network faults, enhancing network reliability. Through logical topology structure analysis, the logical structure and connection relationships in the virtual local area network (VLAN) can be deeply understood to meet the management requirements of the virtualized environment. The logical topology structure model can support flexible network configuration and management, improving network scalability and adaptability. Understanding the logical topology structure helps to optimize the allocation of virtual network resources to ensure the efficient utilization of network resources. By mapping the protocol topology and logical topology models, a comprehensive network topology structure model can be obtained, which can provide a more comprehensive understanding of the actual operation of the network. This comprehensive model provides a more accurate network view, helping to more effectively perform network optimization and problem diagnosis. The network topology structure model can support network planning and decision-making, helping to formulate network expansion and optimization strategies.

[0033] Optionally, step S2 is specifically as follows:

[0034] Step S21: Extract traffic statistical features from the heterogeneous SD-WAN environment monitoring data, so as to obtain traffic statistical data;

[0035] Step S22: Analyze the traffic behavior patterns of network components based on the traffic statistical data, so as to obtain network component traffic behavior pattern data;

[0036] Step S23: Perform similarity evaluation based on the network component traffic behavior pattern data to obtain traffic behavior pattern similarity data;

[0037] Step S24: Perform component traffic behavior pattern clustering on the network component traffic behavior pattern data according to the traffic behavior pattern similarity data to obtain traffic behavior pattern data;

[0038] Step S25: Perform network component traffic behavior pattern marking on the network topology structure model according to the traffic behavior pattern data to obtain a network traffic topology structure model.

[0039] Through the extraction of traffic statistical features from the monitoring data of the heterogeneous SD-WAN environment, the present invention can obtain accurate traffic data, providing basic data for subsequent analysis. This helps to understand the overall patterns and trends of traffic, thus laying a foundation for network optimization. After analyzing the traffic data, the traffic behavior patterns of network components can be identified. This helps to understand the behavior characteristics and load conditions of each component in the network, providing a basis for further traffic management and optimization. By evaluating the similarity of traffic behavior patterns, network components with similar traffic behaviors can be discovered. This process helps to identify components with similar traffic characteristics, thus simplifying subsequent pattern clustering and management. Performing clustering on the network component traffic behavior patterns can group components with similar behaviors. This helps to better organize and manage network components, improving the efficiency of network monitoring and maintenance. Marking the network topology structure model according to the traffic behavior pattern data can provide a detailed view of the network traffic topology structure. This helps to deeply understand the actual traffic patterns of the network, thus enabling more effective network design, optimization, and troubleshooting.

[0040] Optionally, step S22 is specifically as follows:

[0041] Step S221: Extract the network component traffic fluctuation characteristics from the traffic statistical data to obtain network component traffic fluctuation data;

[0042] Step S222: Perform network component traffic benchmark calculation based on the network component traffic fluctuation data to obtain network component traffic benchmark data;

[0043] Step S223: Perform traffic fluctuation stage division on the network component traffic fluctuation data according to the network component traffic benchmark data to obtain network component traffic fluctuation stage division data;

[0044] Step S224: Perform traffic fluctuation periodicity statistics based on the network component traffic fluctuation data to obtain network component traffic fluctuation periodicity data;

[0045] Step S225: Identify and integrate traffic behavior patterns based on data divided by network component traffic fluctuation phases and periodic data of network component traffic fluctuations, thereby obtaining network component traffic behavior pattern data.

[0046] The extraction of traffic fluctuation characteristics in the present invention helps to deeply understand the traffic behavior of network components under different conditions. This provides basic data for identifying traffic anomalies or potential problems, and helps to monitor the network status more accurately. By calculating the traffic baseline, a standard for the normal operation of network components can be established to assist in detecting and diagnosing abnormal conditions. The baseline data provides a reference standard for comparing and evaluating traffic fluctuations. Dividing traffic fluctuations into stages can decompose traffic data into different stages, thereby identifying different fluctuation patterns. This helps to understand the regularity and periodicity of traffic changes and optimize the allocation of network resources. Periodically statistically analyzing traffic fluctuations can reveal regular changes and periodic patterns in traffic. Understanding these patterns helps to predict traffic peaks and troughs and improve the utilization efficiency of network resources. By integrating data divided by traffic fluctuation stages and periodic data and performing behavior pattern recognition, the behavior characteristics of network components can be deeply understood. This helps to optimize network management strategies and enhance network stability and performance.

[0047] Optionally, step S3 is specifically as follows:

[0048] Step S31: Extract network transmission characteristics from heterogeneous SD-WAN environment monitoring data to obtain network transmission data, and calculate the transmission packet loss rate of network components for the network transmission data to obtain component transmission packet loss rate data;

[0049] Step S32: Calculate the traffic jitter of component network links for the network traffic topology structure model to obtain component network link traffic jitter data;

[0050] Step S33: Statistically analyze the traffic jitter baseline for the component network link traffic jitter data to obtain traffic jitter baseline data; statistically analyze the transmission packet loss rate baseline for the component transmission packet loss rate data to obtain transmission packet loss rate baseline data;

[0051] Step S34: Construct a weighted average baseline based on the traffic jitter baseline data and the transmission packet loss rate baseline data to obtain network performance baseline data;

[0052] Step S35: Correct abnormal behaviors of the network traffic topology structure model based on the network performance baseline data to obtain a network traffic corrected topology structure model.

[0053] The present invention extracts network transmission characteristics and calculates the transmission packet loss rate, enabling a clear understanding of the transmission quality of network components. This helps to identify and solve packet loss problems in the network, improving the reliability and stability of data transmission. By calculating the traffic jitter data of the component network link, the link stability and traffic fluctuations can be evaluated. This helps to discover unstable factors in the network link, thereby optimizing network performance. Based on the traffic jitter and transmission packet loss rate data, benchmark statistics are performed to establish standard values for normal operation. This provides a benchmark for evaluating network performance and helps to monitor and compare anomalies in the network state. By constructing network performance benchmark data through weighted average benchmarks, various factors (such as traffic jitter and packet loss rate) can be comprehensively considered to evaluate the overall performance of the network. This helps to comprehensively understand the health status of the network and guides network optimization. According to the network performance benchmark data, the abnormal behavior of the network topology model is corrected, which can correct performance problems and abnormal behaviors in the network. This helps to improve the reliability and stability of the network and ensure the normal transmission of network traffic.

[0054] Optionally, step S35 is specifically as follows:

[0055] Step S351: Classify the abnormal traffic behavior patterns of the traffic behavior pattern data according to the network performance benchmark data, thereby obtaining abnormal traffic behavior pattern data;

[0056] Step S352: Calculate the benchmark error of the abnormal traffic behavior pattern data, thereby obtaining the abnormal traffic behavior pattern benchmark error data;

[0057] Step S353: Conduct low-value benchmark error statistical analysis on the abnormal traffic behavior pattern benchmark error data, thereby obtaining low-value benchmark error pattern data;

[0058] Step S354: Eliminate the low-value benchmark error patterns from the abnormal traffic behavior pattern data according to the low-value benchmark error pattern data, thereby obtaining corrected abnormal traffic behavior pattern data;

[0059] Step S355: Remove the abnormal traffic behavior pattern marks of network components from the network traffic topology model according to the corrected abnormal traffic behavior pattern data, thereby obtaining a corrected network traffic topology model.

[0060] The abnormal classification of traffic behavior patterns in the present invention can identify and isolate abnormal traffic patterns. This helps to more accurately locate the potential problem sources and optimize network traffic management. Calculating the benchmark error of abnormal traffic behavior patterns can quantify the deviation of abnormal behaviors. This helps to understand the severity of abnormal patterns and provide a quantitative basis for subsequent adjustments. Statistical analysis of low benchmark errors can identify and focus on those patterns with small errors but may affect network performance. This helps to optimize the identification of subtle but potential performance problems and improve the overall stability of the network. Eliminating low benchmark error patterns can reduce the misjudgment of abnormal traffic behaviors, thereby improving the accuracy of abnormal patterns and the effect of network correction. Applying the corrected abnormal traffic behavior patterns to the network topology model helps to eliminate abnormal traffic patterns in the markings, thereby improving the reliability and performance of the network.

[0061] Optionally, step S4 is specifically as follows:

[0062] Step S41: Extract the network component resource allocation characteristics from the heterogeneous SD-WAN environment monitoring data to obtain the network component resource allocation data;

[0063] Step S42: Integrate the traffic behavior patterns of the network traffic correction topology model to obtain the traffic behavior pattern correction data;

[0064] Step S43: Perform spatio-temporal traffic dimension data fusion on the traffic behavior pattern correction data and the network component resource allocation data through the network traffic correction topology model to obtain the spatio-temporal traffic dimension fusion model;

[0065] Step S44: Evaluate the network performance of network components according to the spatio-temporal traffic dimension fusion model to obtain the network component network performance evaluation data;

[0066] Step S45: Perform traffic-resource utilization time-series correlation visualization according to the network component network performance evaluation data to obtain the network performance analysis report.

[0067] By extracting features, the present invention can identify resource bottlenecks or uneven resource allocation in the network, and thus take measures for optimization. The provided data can help network administrators make data-based decisions, optimize the allocation of network resources, improve the overall network performance, and provide necessary baseline data for subsequent performance evaluation. By integrating traffic behavior patterns, the changing trends and behavior characteristics of traffic can be more clearly understood, which helps to predict and manage traffic demands in advance. A profound understanding of traffic behavior patterns helps to optimize network design and configuration, ensure that the network can efficiently handle expected traffic loads, reduce network congestion, and improve response speed, thereby enhancing the experience of end users. Through the fusion of time-space dimensions, more comprehensive traffic analysis can be carried out, understanding the changes in traffic at different times and in different spaces, providing the ability to predict future traffic demands, and enabling measures to be taken in advance to prevent network performance degradation. By evaluating the performance of network components, the network status can be monitored in real time, performance problems can be discovered and solved in a timely manner, which is beneficial to improving the stability and reliability of the network and reducing the risk of network failures and service interruptions. Through the visualization of time-series correlation, the usage of traffic and resources can be intuitively displayed, helping network administrators better understand the data. The generated performance analysis report can be used as a decision support tool to assist in formulating future network planning and resource allocation strategies.

[0068] Optionally, the present invention further provides a heterogeneous SD-WAN fusion monitoring system for performing a heterogeneous SD-WAN fusion monitoring method as described above. The heterogeneous SD-WAN fusion monitoring system includes:

[0069] A network topology structure modeling module, configured to obtain heterogeneous SD-WAN environment monitoring data, analyze the connection types of network components based on the heterogeneous SD-WAN environment monitoring data to obtain network component connection type data; and perform heterogeneous SD-WAN network topology structure modeling based on the network component connection type data to obtain a network topology structure model;

[0070] A traffic pattern classification module, configured to extract traffic statistical features from the heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data, and analyze traffic behavior patterns based on the traffic statistical data to obtain traffic behavior pattern data; and perform traffic pattern classification and marking on the network topology structure model according to the traffic behavior pattern data to obtain a network traffic topology structure model;

[0071] An abnormal behavior correction module, configured to construct a performance benchmark based on the network traffic topology structure model and the heterogeneous SD-WAN environment monitoring data to obtain network performance benchmark data, and perform abnormal behavior correction on the network traffic topology structure model according to the network performance benchmark data to obtain a network traffic corrected topology structure model;

[0072] A multi-dimensional data fusion module is used to extract the characteristics of network component resource allocation from the monitoring data of heterogeneous SD-WAN environments, so as to obtain network component resource allocation data; the multi-dimensional data fusion is performed on the network component resource allocation data through a network traffic correction topology model, so as to obtain a network performance analysis report.

[0073] A resource allocation strategy optimization module is used to optimize the component resource allocation strategy based on the network performance analysis report for the network component resource allocation data, so as to obtain an optimized network component resource allocation strategy and upload it to the heterogeneous SD-WAN network management platform to execute the resource allocation optimization task.

[0074] The heterogeneous SD-WAN fusion monitoring system of the present invention can implement any one of the heterogeneous SD-WAN fusion monitoring methods of the present invention, and is used as a medium for coordinating the operations and signal transmissions between each module to complete the heterogeneous SD-WAN fusion monitoring method. The internal modules of the system cooperate with each other, thereby improving the overall network management efficiency. Description of the Drawings

[0075] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives, and advantages of the present invention will become more obvious:

[0076] Figure 1 It is a schematic flowchart of the steps of the heterogeneous SD-WAN fusion monitoring method of the present invention;

[0077] Figure 2 It is a detailed schematic flowchart of step S1 in the present invention;

[0078] Figure 3 It is a detailed schematic flowchart of step S12 in the present invention;

[0079] The realization, functional characteristics, and advantages of the objectives of the present invention will be further described with reference to the embodiments and the drawings. Detailed Embodiments

[0080] The technical method of the present invention will be clearly and completely described below with reference to the drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0081] In addition, the accompanying drawings are only schematic illustrations of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities may be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.

[0082] It should be understood that although the terms "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.

[0083] To achieve the above object, please refer to Figures 1 to 3 , the present invention provides a heterogeneous SD-WAN fusion monitoring method, and the method includes the following steps:

[0084] Step S1: Obtain heterogeneous SD-WAN environment monitoring data, and perform network component connection type analysis based on the heterogeneous SD-WAN environment monitoring data to obtain network component connection type data; perform heterogeneous SD-WAN network topology structure modeling based on the network component connection type data to obtain a network topology structure model;

[0085] In this embodiment, first, collect monitoring data from a heterogeneous SD-WAN environment, such as device logs, connection status, and bandwidth usage. These data can be obtained in real time through a network monitoring system (such as SNMP, NetFlow, or sFlow). By analyzing the connection status between network components, determine the connection type (such as point-to-point, star, mesh, etc.). Use a network topology modeling tool (such as Graphviz or Gephi) to model these connection types and create a network topology structure model. The model may include nodes (network components) and edges (connection lines), and the connection types of each node are detailedly marked. For example, some nodes may be connected through high-bandwidth links, while other nodes may be connected through low-bandwidth links.

[0086] Step S2: Extract traffic statistical features from the heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data, and perform traffic behavior pattern analysis based on the traffic statistical data to obtain traffic behavior pattern data; classify and label the traffic patterns of the network topology structure model according to the traffic behavior pattern data to obtain the network traffic topology structure model;

[0087] In this embodiment, traffic statistical feature data is extracted from the SD-WAN environment, such as the traffic volume per hour, traffic sources and destinations, and traffic types (HTTP, FTP, etc.). Traffic analysis tools (such as Wireshark, NetFlowAnalyzer) are used to analyze these data to identify common traffic patterns (such as peak-hour traffic, normal traffic patterns, abnormal traffic patterns). These traffic behavior patterns are labeled into the network topology structure model. For example, certain network links may show high traffic patterns during working hours and low traffic patterns during non-working hours. This process helps identify traffic peaks, bottlenecks, and potential load imbalances.

[0088] Step S3: Construct a performance benchmark based on the network traffic topology structure model and the heterogeneous SD-WAN environment monitoring data to obtain network performance benchmark data, and perform abnormal behavior correction on the network traffic topology structure model according to the network performance benchmark data to obtain the network traffic corrected topology structure model;

[0089] In this embodiment, a network performance benchmark is constructed based on the network traffic topology structure model and the heterogeneous SD-WAN environment monitoring data. This includes calculating various performance metrics, such as latency, throughput, packet loss rate, etc. Using these metrics, a network performance benchmark data model is established. Then, the benchmark data is compared with real-time monitoring data to identify abnormal behaviors. For example, if it is found that the latency of a certain link is significantly higher than the benchmark value, this may indicate that the link has a fault or is overloaded. Based on these findings, the network topology structure model is adjusted to correct the abnormal behavior and generate a corrected network topology structure model.

[0090] Step S4: Extract network component resource allocation features from the heterogeneous SD-WAN environment monitoring data to obtain network component resource allocation data; perform multi-dimensional data fusion on the network component resource allocation data through the network traffic corrected topology structure model to obtain a network performance analysis report;

[0091] In this embodiment, network component resource allocation feature data such as CPU usage, memory occupancy, bandwidth allocation, etc. are extracted from the SD-WAN monitoring data. Using the previous network traffic calibration topology model, these data are fused in multiple dimensions. For example, by combining traffic behavior patterns and resource usage, it is determined which components' resource allocations need to be adjusted. A network performance analysis report is generated, detailing the resource allocation status, traffic patterns, and their impact on performance.

[0092] Step S5: Optimize the component resource allocation strategy for the network component resource allocation data based on the network performance analysis report, thereby obtaining an optimized network component resource allocation strategy and uploading it to the heterogeneous SD-WAN network management platform to execute the resource allocation optimization task.

[0093] In this embodiment, the network component resource allocation is optimized based on the network performance analysis report. For example, by analyzing the report, it is found that the bandwidth resource allocation of some nodes is insufficient while other nodes have idle resources. The optimization strategy can include reallocating bandwidth, adding a load balancing mechanism, etc. The optimized resource allocation strategy is formulated and uploaded to the heterogeneous SD-WAN network management platform. Through the platform, the policy adjustment is executed. For example, the device configuration is adjusted or the traffic routing is modified to ensure that the network resources are optimally configured and the overall network performance is improved.

[0094] Optionally, step S1 is specifically as follows:

[0095] Step S11: Obtain the heterogeneous SD-WAN environment monitoring data and extract the network component connection features from the heterogeneous SD-WAN environment monitoring data, thereby obtaining the network component connection data;

[0096] In this embodiment, various types of monitoring data need to be collected from the heterogeneous SD-WAN environment first, including but not limited to traffic data, latency data, packet loss rate, bandwidth usage, etc. The specific operation can be achieved by configuring the management interfaces of network devices (such as SNMP, NetFlow, or sFlow) to collect the data. Then, data parsing tools are used to convert the original monitoring data into structured network component connection data. For example, the connection statuses of different network devices and the link performance data are extracted, and a connection feature data model is established based on the IP addresses and port information of the devices for subsequent processing.

[0097] Step S12: Classify the network component connection data by the network component connection type, thereby obtaining the network component connection type data;

[0098] In this embodiment, it is necessary to classify the extracted network component connection data into different types of connection statuses, such as: normal, faulty, overloaded, etc. Machine learning algorithms (such as decision trees, support vector machines, or neural networks) can be used to train and classify the connection data. To achieve efficient classification, a classification model needs to be trained based on the connection data features (such as latency, packet loss rate, bandwidth occupancy, etc.). Using labeled data for training, the model can automatically classify real-time network connection data into different statuses and generate a report on the network component connection type data.

[0099] Step S13: Integrate the connection relationships of the network center components according to the network component connection type data, so as to obtain the center component connection relationship data;

[0100] In this embodiment, it is first necessary to identify the network center components, such as core routers, switches, etc., and integrate the connection relationships between these center components according to the network component connection type data. This involves analyzing the network topology and integrating the connection situations of each center component in the network into a comprehensive center component connection relationship diagram. For example, by summarizing the connection statuses of all center components, a connection matrix between the center components is formed to describe their connection strength, stability, and load conditions, so as to obtain the center component connection relationship data.

[0101] Step S14: Analyze the network communication topology structure based on the center component connection relationship data, so as to obtain the network topology structure model.

[0102] In this embodiment, it is necessary to use the obtained center component connection relationship data to construct and analyze the network communication topology structure. First, input the center component connection relationship data into network topology modeling tools, which can construct the network topology structure based on graph theory models (such as nodes and edges of a graph). Secondly, by analyzing the connectivity, node importance, traffic distribution, etc. of the network topology, a network topology structure model is generated. Network visualization tools (such as Gephi, Cytoscape) can be used to display the network topology structure, so as to help understand the overall architecture of the network and optimize the network performance.

[0103] Optionally, step S12 is specifically:

[0104] Step S121: Count the component connection frequencies of the network component connection data, so as to obtain high-frequency connection component data and low-frequency connection component data;

[0105] In this embodiment, connection data between all network components is collected. The connections between each pair of components are recorded and counted. For example, assume that the network contains 100 components. By recording and analyzing the number of connections between these components, connection frequency data of each component with other components is obtained. The statistical results may show that the connection frequency between component A and component B is 50 times, and the connection frequency between component C and component D is 10 times. Sort these data to determine high-frequency connection component data (pairs of components with high connection times) and low-frequency connection component data (pairs of components with low connection times). The connection frequency statistics should take into account the connection data of all component pairs in the network to ensure comprehensive and accurate statistics. The statistical data should have a certain time window to capture the dynamic changes in connections.

[0106] Step S122: Select the components with the highest frequency connections according to the high-frequency connection component data, so as to obtain network center component data;

[0107] In this embodiment, according to the obtained high-frequency connection component data, select the pair of components with the highest connection frequency. For example, assume that in the high-frequency connection component data, the connection frequency between component A and component B is the highest, which is 50 times. Therefore, component A and component B are marked as network center components. The selected pair of components will be used as the network center component data for subsequent analysis. The selection criteria should be based on the connection frequency, and a threshold (such as the top 5% of component pairs) should be set to determine the components with the highest frequency connections. Pairs of components with too low frequencies should be avoided to ensure that the selection results are representative.

[0108] Step S123: Statistically analyze the connection frequencies of the high-frequency connection component data and the low-frequency connection component data according to the network center component data, so as to obtain high-frequency center component connection component data and low-frequency center component connection component data;

[0109] In this embodiment, using the network center component data (such as component A and B), statistically analyze the connection frequencies of these center components with the high-frequency connection component data and the low-frequency connection component data. For example, assume that the connection frequency between component A and multiple high-frequency connection components is 60 times, and the connection frequency with low-frequency connection components is 5 times. In this way, high-frequency center component connection component data (connection components with high frequencies) and low-frequency center component connection component data (connection components with low frequencies) are obtained. The connection frequency statistics should be specifically carried out for the data of the center components to determine their core roles in the network. The statistical method should be able to accurately distinguish high-frequency and low-frequency connections.

[0110] Step S124: Extract the component network connection delay characteristics according to the network component connection data, so as to obtain component network connection delay data;

[0111] In this embodiment, the connection delays between network components are measured and feature extracted. For example, the recorded delay time of the connection between component A and component B is 30 milliseconds, and the connection delay between component C and component D is 120 milliseconds. The delay data is extracted and statistically analyzed to obtain the network connection delay data of the components. For example, the connection delay between component A and B is low delay, while the connection delay between component C and D is high delay. The delay feature extraction should be performed at different time points to capture the dynamic changes in the connection delay. The delay data should have a sufficient sample size to improve the reliability of the statistical results.

[0112] Step S125: Classify the network delay components according to the network connection delay data of the components, so as to obtain the high-delay connection component data and the low-delay connection component data;

[0113] In this embodiment, according to the extracted delay data, the component connections are classified according to the delay time. For example, connections with a delay less than 50 milliseconds are marked as low-delay connections, and connections with a delay greater than 100 milliseconds are marked as high-delay connections. The high-delay connection component data and the low-delay connection component data are obtained. The delay classification should be based on clear thresholds, such as the dividing line between 50 milliseconds and 100 milliseconds. The actual usage of the network should be taken into account to ensure the practical significance of the classification results.

[0114] Step S126: Perform an intersection operation on the high-frequency center component connection component data and the low-delay connection component data to obtain the normal network connection component data; perform an intersection operation on the low-frequency center component connection component data and the high-delay connection component data to obtain the temporary network connection component data;

[0115] In this embodiment, an intersection operation is performed on the high-frequency center component connection component data and the low-delay connection component data to obtain the normal network connection component data. An intersection operation is performed on the low-frequency center component connection component data and the high-delay connection component data to obtain the temporary network connection component data. For example, the high-frequency center component connection component data includes component A and B, and the low-delay connection component data includes component A and C. Therefore, the normal network connection component data is component A.

[0116] Step S127: Merge the component connections according to the network center component data, the normal network connection component data, and the temporary network connection component data to obtain the network component connection type data.

[0117] In this embodiment, based on the data of the network center components, the normal network connection components, and the temporary network connection components, these data are merged. For example, the central component (such as component A), the normal network connection component (such as component B), and the temporary network connection component (such as component C) are merged to obtain the network component connection type data. This kind of merging can provide a comprehensive view of the network component connection type. The merging process should be able to comprehensively consider the characteristics of various types of data to obtain a comprehensive and accurate network component connection type data. The merging result should be verified to ensure that it represents the actual network connection situation.

[0118] Optionally, step S14 is specifically as follows:

[0119] Step S141: Extract the component routing protocol features from the heterogeneous SD-WAN environment monitoring data, so as to obtain the component routing protocol data;

[0120] In this embodiment, when extracting features from the monitoring data of the heterogeneous SD-WAN environment, it is first necessary to extract the routing protocol features of each component from the data. For example, the packet traffic, switching rate, and link state information of protocols such as BGP, OSPF, or EIGRP are used. This can be achieved through network traffic analysis tools, which can parse the data and extract the protocol features to generate a data table containing each routing protocol.

[0121] Step S142: Perform component routing protocol clustering according to the component routing protocol data, so as to obtain the routing protocol clustering component data;

[0122] In this embodiment, when performing component routing protocol clustering, clustering algorithms (such as K-means or DBSCAN) can be used to classify the extracted routing protocol data. By analyzing the features such as the traffic pattern, delay, and bandwidth usage of the protocols, the protocols with similar features are grouped into one category, so as to obtain the routing protocol clustering component data. The key to this step is to select appropriate clustering parameters and algorithms for accurate classification.

[0123] Step S143: Perform network protocol topology structure analysis according to the routing protocol clustering component data and the network component connection data, so as to obtain the network protocol topology structure model;

[0124] In this embodiment, the routing protocol clustering component data and the network component connection data (such as the connection relationship between switches and routers) are used to perform network protocol topology structure analysis. Algorithms in graph theory (such as the shortest path algorithm or the minimum spanning tree algorithm) can be applied to construct the network topology structure model, which describes the connection relationship between components in the network and the data flow path.

[0125] Step S144: Analyze the virtual local area network (VLAN) logical topology structure based on the central component connection relationship data to obtain a network logical topology structure model;

[0126] In this embodiment, in the analysis of the VLAN logical topology structure, based on the connection relationship data of the central components (such as the connection situation between the core switch and each terminal), identify and draw the logical topology structure of the virtual local area network (VLAN). A logical network diagram drawing tool can be used to analyze the connection mode of the central nodes and draw a logical network topology structure model, which shows the virtual network relationships within the VLAN.

[0127] Step S145: Perform topology mapping on the network protocol topology structure model and the network logical topology structure model to obtain a network topology structure model.

[0128] In this embodiment, map the obtained network protocol topology structure model and the obtained network logical topology structure model. This process includes aligning the physical connection relationships in the network protocol topology with the virtual network relationships in the logical topology to obtain the final network topology structure model. A data mapping tool can be used to integrate the data of the two models to generate a model that comprehensively describes the network structure, which can show the network layout at the physical and logical levels.

[0129] Optionally, step S2 is specifically as follows:

[0130] Step S21: Extract traffic statistical features from the heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data;

[0131] In this embodiment, in the heterogeneous SD-WAN environment, when extracting traffic statistical features, first collect the traffic data of each network component, including the traffic rate per second, packet size, traffic direction, etc. Use traffic monitoring tools such as NetFlow or sFlow to extract this data and calculate statistical features such as the average value, variance, and peak value of the traffic. These features can help understand the traffic behavior of different network components and provide basic data for subsequent analysis.

[0132] Step S22: Analyze the traffic behavior patterns of network components based on the traffic statistical data to obtain network component traffic behavior pattern data;

[0133] In this embodiment, based on the extracted traffic statistical data, use a machine learning model (such as clustering analysis or classification model) to analyze the traffic behavior patterns of network components. For example, use the K-means clustering algorithm to group network components with similar traffic features. This can identify common patterns of traffic behavior, such as traffic surges during peak hours or the traffic distribution of specific applications.

[0134] Step S23: Perform similarity evaluation based on the network component traffic behavior pattern data to obtain traffic behavior pattern similarity data;

[0135] In this embodiment, when performing similarity evaluation on the network component traffic behavior pattern data, an appropriate similarity metric standard (such as Euclidean distance, cosine similarity, etc.) is selected to calculate the similarity between each traffic pattern. For example, the cosine similarity is used to calculate the similarity between the traffic behavior patterns of different network components, thereby identifying similar traffic behavior patterns.

[0136] Step S24: Cluster the network component traffic behavior pattern data according to the traffic behavior pattern similarity data to obtain traffic behavior pattern data;

[0137] In this embodiment, clustering analysis is performed on the traffic behavior patterns of network components according to the similarity data. For example, the hierarchical clustering algorithm is used to group traffic patterns with high similarity into the same group, thereby forming several main traffic pattern groups. Each group represents a specific traffic behavior pattern, which is convenient for understanding and managing network traffic.

[0138] Step S25: Mark the network component traffic behavior pattern on the network topology structure model according to the traffic behavior pattern data to obtain the network traffic topology structure model.

[0139] In this embodiment, the obtained traffic behavior pattern data is marked on the network topology structure model. By mapping the traffic behavior pattern of each network component to the corresponding node or link on the network topology diagram, a marked network topology model is formed. This can help visualize the network traffic pattern and mark the characteristics of the traffic behavior in the network topology structure, which is convenient for further network optimization and fault troubleshooting.

[0140] Optionally, step S22 is specifically:

[0141] Step S221: Extract the network component traffic fluctuation characteristics from the traffic statistical data to obtain network component traffic fluctuation data;

[0142] In this embodiment, traffic statistical data of network components (such as routers, switches) is collected, and the data includes information such as traffic per second, packet loss rate, and delay. These data are sampled at regular intervals (such as every minute) within a period of time. Statistical analysis tools, such as moving average or smoothing filters, are used to preprocess the original data to remove noise. Then, features such as the standard deviation, peak value, and fluctuation range of the traffic are calculated. These features reflect the fluctuation degree and trend of the network traffic. For example, by calculating the standard deviation of the traffic within 10 minutes, the traffic fluctuation situation during this period can be determined, thereby extracting the fluctuation characteristic data of the network component traffic.

[0143] Step S222: Calculate the network component traffic baseline based on the network component traffic fluctuation data, so as to obtain the network component traffic baseline data;

[0144] In this embodiment, after obtaining the traffic fluctuation characteristics of the network component, the traffic baseline calculation is performed. First, define a baseline time period (for example, one week), and then calculate the traffic mean value at each time point within this time period. These mean values serve as the baseline traffic values. Statistical methods, such as moving average or linear regression, are used to smooth the traffic data and generate a baseline traffic curve. By comparing with historical data, the baseline value of the traffic and its deviation can be calculated. For example, if the average traffic of a network component in the past week is 100 Mbps, then this value is used as the traffic baseline data for subsequent fluctuation analysis and anomaly detection.

[0145] Step S223: Divide the network component traffic fluctuation data into stages based on the network component traffic baseline data, so as to obtain the network component traffic fluctuation stage division data;

[0146] In this embodiment, based on the traffic baseline data, the traffic fluctuation data is divided into stages. First, by analyzing the traffic baseline data, determine the range of normal traffic (for example, within ±10% of the baseline traffic). Then, segment the traffic fluctuation data and mark whether the traffic in each time period exceeds the normal range. Use a clustering algorithm (such as K-means clustering) to divide the traffic data into different stages, such as the normal stage, the slight fluctuation stage, and the severe fluctuation stage. If the traffic is within ±10% of the baseline value, it is marked as "normal", and if it exceeds ±20%, it is marked as "severe fluctuation", so as to obtain the traffic fluctuation stage division data.

[0147] Step S224: Perform traffic fluctuation periodic statistics based on the network component traffic fluctuation data, so as to obtain the network component traffic fluctuation periodic data;

[0148] In this embodiment, in order to analyze the periodicity of the traffic, first perform frequency domain analysis on the traffic fluctuation data using the Fourier transform (FFT) or periodogram analysis tool. Identify the main periodic patterns existing in the traffic data, such as the daily peak and trough periods. Determine the periodic characteristics of the traffic through statistical analysis, such as the periodic fluctuations every 24 hours, every week, and every month. For example, it is found that the traffic of a certain network component is the highest between 8:00 - 10:00 every day and the lowest between 2:00 - 4:00 in the late night. According to these periodic data, calculate the length and amplitude of the period to obtain the network component traffic fluctuation periodic data.

[0149] Step S225: Classify the data according to the traffic fluctuation stages of network components and integrate the periodic data of network component traffic fluctuations to identify and integrate traffic behavior patterns, thereby obtaining network component traffic behavior pattern data.

[0150] In this embodiment, by combining the data classified according to traffic fluctuation stages and the periodic statistical data, traffic behavior pattern recognition is performed. First, the stage-based classification data is matched with the periodic data to identify the periodic patterns in different stages. Machine learning algorithms such as decision trees or support vector machines (SVMs) are applied to train models to identify common traffic behavior patterns. For example, the model identifies the relationship between the drastic fluctuation pattern of traffic during peak hours and system anomalies. Integrate these pattern data to generate the traffic behavior pattern data of network components. Finally, the network management strategy can be optimized through the pattern recognition results for early warning and resource allocation.

[0151] Optionally, step S3 is specifically as follows:

[0152] Step S31: Extract the network transmission characteristics from the monitoring data of the heterogeneous SD-WAN environment to obtain network transmission data, and calculate the transmission packet loss rate of network components for the network transmission data to obtain component transmission packet loss rate data;

[0153] In this embodiment, in a heterogeneous SD-WAN environment, it is necessary to collect network transmission data from different types of network devices (such as routers, switches, firewalls). These data usually include the number of packet transmissions per second, transmission delay, packet loss rate, etc. First, obtain the detailed transmission logs of packets through network traffic monitoring tools (such as NetFlow, sFlow) or network management systems (NMS). Then, use data analysis tools (such as the Pandas library in Python) to process these logs and calculate the transmission packet loss rate of each network component. This calculation process includes collecting the number of packets sent and received within a specific time period, and dividing the number of lost packets by the total number of sent packets to obtain the component transmission packet loss rate data. For example, for a certain router that sent 1000 packets in one hour, but only 950 packets were received at the receiving end, then the packet loss rate is (1000 - 950) / 1000 = 5%.

[0154] Step S32: Calculate the traffic jitter of component network links for the network traffic topology structure model to obtain component network link traffic jitter data;

[0155] In this embodiment, for the network traffic topology structure model, it is necessary to calculate the traffic jitter of each network link. Traffic jitter refers to the fluctuation of packet delay during transmission. First, use a traffic monitoring tool to collect the packet delay time of each link, and then perform statistical analysis on these delay times. In specific implementation, select a time window (such as every minute), and collect the delay time of the packets within this time window (for example, obtain it through SNMP or NetFlow). Calculate the standard deviation or coefficient of variation of these delay times as the link traffic jitter data. For example, if the packet delay times in a certain link are 20ms, 22ms, 19ms, and 30ms respectively, then its jitter is the standard deviation of these delay times, that is, sqrt(((20 - 22)^2+(22 - 19)^2+(19 - 22)^2+(30 - 22)^2) / 4)=5.4ms.

[0156] Step S33: Conduct traffic jitter baseline statistics on the component network link traffic jitter data to obtain traffic jitter baseline data; conduct transmission packet loss rate baseline statistics on the component transmission packet loss rate data to obtain transmission packet loss rate baseline data;

[0157] In this embodiment, to conduct baseline statistics on the component network link traffic jitter data, it is necessary to collect historical data within a certain time range and calculate its statistical characteristics. Select a network topology map containing multiple links, and collect the traffic jitter data of each link in the past week. Then calculate indicators such as the average value and standard deviation of the traffic jitter as the traffic jitter baseline data. For example, the jitter data of a certain link in the past week are 5ms, 4ms, 6ms, and 7ms respectively, and its traffic jitter baseline is the mean and standard deviation of these data: the mean is 5.5ms, and the standard deviation is 1.2ms. At the same time, conduct the same baseline statistics on the component transmission packet loss rate data.

[0158] Step S34: Construct a weighted average baseline based on the traffic jitter baseline data and the transmission packet loss rate baseline data to obtain network performance baseline data;

[0159] In this embodiment, use the traffic jitter baseline data and the transmission packet loss rate baseline data to construct the network performance baseline. Weight and average the traffic jitter baseline data and the transmission packet loss rate baseline data according to a certain weight to obtain comprehensive network performance baseline data. For example, it is set that the traffic jitter accounts for 60% of the total performance index, and the transmission packet loss rate accounts for 40%. If the traffic jitter baseline is 5ms and the transmission packet loss rate baseline is 3%, then the network performance baseline is 0.6×5ms + 0.4×3% = 3ms + 1.2% (comprehensive result based on relative units).

[0160] Step S35: Correct the abnormal behavior of the network traffic topology model according to the network performance benchmark data, so as to obtain the corrected network traffic topology model.

[0161] In this embodiment, after obtaining the network performance benchmark data, it is necessary to correct the network traffic topology model to correct any abnormal behavior. First, by comparing the actual traffic data with the benchmark data, the links or components whose performance indicators exceed the normal range are identified. Then, apply correction algorithms (such as machine learning models or rule engines) to adjust the network traffic topology model to optimize network performance. For example, if it is found that the traffic jitter of a certain link is significantly higher than the benchmark value, the network topology model can be corrected by reconfiguring the link priority, adjusting the bandwidth allocation, or introducing traffic shaping strategies. Finally, the updated network traffic topology model can more accurately reflect the actual performance state of the network.

[0162] Optionally, step S35 is specifically:

[0163] Step S351: Classify the abnormal traffic behavior patterns of the traffic behavior pattern data according to the network performance benchmark data, so as to obtain the abnormal traffic behavior pattern data;

[0164] In this embodiment, a machine learning model (such as the K-means clustering algorithm) is used to train the network performance benchmark data to identify the normal traffic patterns. Then, the real-time traffic behavior pattern data is input into the model for anomaly detection. The abnormal traffic behavior patterns are marked as the data with significant deviation from the normal patterns in the training model. For example, if the average delay of normal traffic is 10ms and the standard deviation is 2ms, and the average delay of some data in the real-time behavior pattern data is 30ms, deviating from the normal pattern by more than 3 standard deviations, these data will be classified as abnormal traffic behavior pattern data.

[0165] Step S352: Calculate the benchmark error of the abnormal traffic behavior pattern data, so as to obtain the abnormal traffic behavior pattern benchmark error data;

[0166] In this embodiment, the identified abnormal traffic behavior pattern data is compared with the network performance benchmark data. Statistical methods (such as mean absolute error, root mean square error, etc.) are used to calculate the error between the abnormal data and the normal benchmark data. For example, if the throughput of a certain traffic is 100Mbps under normal conditions and 150Mbps under abnormal conditions, the throughput error is 50Mbps. This calculation is performed on all abnormal traffic pattern data, and the obtained error values form the abnormal traffic behavior pattern benchmark error data.

[0167] Step S353: Conduct low-amount benchmark error statistical analysis on the abnormal traffic behavior pattern benchmark error data, so as to obtain the low-amount benchmark error pattern data;

[0168] In this embodiment, statistical analysis is performed on the abnormal traffic behavior pattern benchmark error data to identify data patterns with lower errors. A statistical analysis tool (such as the ggplot2 package in R language) is used to draw an error distribution graph, and low-error patterns are extracted from it. For example, assume that through analysis, it is found that most of the error values in the abnormal data are concentrated in the range of 0 - 10 Mbps, which indicates that the error of these data patterns is relatively low. Through this analysis, data with low benchmark error patterns can be marked and extracted as the basis for further analysis.

[0169] Step S354: Eliminate the low benchmark error patterns from the abnormal traffic behavior pattern data according to the low benchmark error pattern data, so as to obtain the corrected abnormal traffic behavior pattern data;

[0170] In this embodiment, the obtained low benchmark error pattern data is used to screen the abnormal traffic behavior pattern data. The low benchmark error pattern data usually represents patterns with relatively small errors, which may be caused by short-term fluctuations or other non-major factors. Therefore, these patterns are eliminated from the overall abnormal traffic data. Data processing software (such as the Pandas library in Python) can be used to filter data according to an error threshold (such as an error less than 10 Mbps). For example, create a conditional screening function to exclude data with error values lower than 10 Mbps, and the resulting data is the corrected abnormal traffic behavior pattern data.

[0171] Step S355: Eliminate the abnormal traffic behavior patterns of network components from the network traffic topology structure model according to the corrected abnormal traffic behavior pattern data, so as to obtain a corrected network traffic topology structure model.

[0172] In this embodiment, the network traffic topology structure model is adjusted according to the obtained corrected abnormal traffic behavior pattern data. First, identify each network component (such as routers, switches, etc.) in the topology model, and then mark the abnormal traffic behavior patterns of these components in the model. Use a computer network simulation tool (such as GNS3 or NS3) to re-model the network traffic, and eliminate or correct the marked abnormal patterns. For example, assume that a certain router shows high latency and packet loss rate in abnormal traffic. Through model adjustment, the abnormal traffic patterns of these components are eliminated or reduced to obtain a corrected network traffic topology structure model to optimize the overall network performance. It is also possible to eliminate or correct the marked traffic behavior patterns in the network traffic topology structure model to identify abnormal patterns existing in the components.

[0173] Optionally, step S4 is specifically as follows:

[0174] Step S41: Extract the resource allocation characteristics of network components from the heterogeneous SD-WAN environment monitoring data to obtain the network component resource allocation data;

[0175] In this embodiment, in the heterogeneous SD-WAN environment, network monitoring data is first collected from multiple data sources (such as routers, switches, link status monitoring systems, etc.). These data include traffic load, bandwidth utilization rate, latency, packet loss rate, etc. Then, data preprocessing techniques (such as data cleaning and standardization) are used to extract the resource allocation characteristics of network components (such as devices, links), such as the bandwidth allocation, CPU, and memory usage of each device. Feature selection algorithms (such as principal component analysis or correlation analysis) are used to identify the resource allocation characteristics that have a greater impact on network performance and generate a network component resource allocation dataset for subsequent analysis.

[0176] Step S42: Integrate the traffic behavior patterns of the network traffic correction topology structure model to obtain the traffic behavior pattern correction data;

[0177] In this embodiment, when constructing the network traffic correction topology structure model, the network traffic is first monitored and recorded in real time, including the traffic data, traffic paths, and traffic fluctuations of each node. Machine learning algorithms (such as clustering analysis or time series analysis) are used to identify different traffic behavior patterns, such as periodic peak traffic or burst traffic behavior. These patterns are integrated with the topology structure model to form the traffic behavior pattern correction data. These data include the performance of various traffic patterns in the topology structure, such as traffic bottlenecks, abnormal traffic paths, etc. It is also possible to extract the traffic behavior patterns of each network component that has been marked in the network traffic correction topology structure model, and then integrate these behavior patterns to obtain the traffic behavior pattern correction data.

[0178] Step S43: Perform spatio-temporal traffic dimension data fusion on the traffic behavior pattern correction data and the network component resource allocation data through the network traffic correction topology structure model to obtain the spatio-temporal traffic dimension fusion model;

[0179] In this embodiment, the generated network component resource allocation data, traffic behavior pattern correction data, and traffic type data are input into the spatio-temporal traffic dimension data fusion model. This model can perform spatio-temporal dimension fusion analysis on the data based on a deep learning network (such as a temporal convolutional network or a recurrent neural network). By combining time series features (such as the time variation of traffic) and spatial features (such as the node positions in the network topology), the model can output a comprehensive spatio-temporal traffic dimension fusion model, comprehensively reflecting the variation laws of traffic in terms of time, space, and type and their impact on network performance. Deep learning methods, such as long short-term memory networks (LSTM) combined with convolutional neural networks (CNN), can be used to capture the temporal and spatial dependencies in the traffic data.

[0180] Step S44: Perform network component network performance evaluation according to the spatio-temporal traffic dimension fusion model, so as to obtain network component network performance evaluation data;

[0181] In this embodiment, the generated spatio-temporal traffic dimension fusion model is used to comprehensively evaluate the performance of network components. The fusion model is applied to actual network data to evaluate the performance metrics (such as throughput, latency, packet loss rate) of each network component (such as routers, switches). Performance evaluation algorithms (such as weighted average method or multi-objective optimization) are used to quantify the performance of different components, generating network component network performance evaluation data. These data reflect the actual performance and bottlenecks of each component under the current traffic pattern and resource allocation. For example, weights are assigned to each performance metric of the network component, and a comprehensive score is calculated. For example, the weights of throughput, latency, and packet loss rate are set to 40%, 30%, and 30%, respectively, and then the weighted average score is calculated. According to the results of the weighted average method or multi-objective optimization, a comprehensive score for each network component is generated. For example, for a certain router, the comprehensive score includes its performance in terms of throughput, latency, and packet loss rate.

[0182] Step S45: Perform traffic-resource utilization time series correlation visualization according to the network component network performance evaluation data, so as to obtain a network performance analysis report.

[0183] In this embodiment, the obtained network performance evaluation data are input into the traffic-resource utilization time series correlation visualization tool. Data visualization techniques (such as time series graphs, heat maps, relationship graphs) are used to display the changing trends of network performance data and resource utilization. The tool can support interactive visualization, allowing users to view the detailed performance information of specific time periods or specific network components. Through this visualization, users can identify the relationship between traffic patterns and resource allocation, understand the reasons for changes in network performance, and generate a network performance analysis report to help network administrators optimize network configuration and resource allocation strategies.

[0184] Optionally, the present invention further provides a heterogeneous SD-WAN fusion monitoring system for implementing a heterogeneous SD-WAN fusion monitoring method as described above. The heterogeneous SD-WAN fusion monitoring system includes:

[0185] A network topology structure modeling module, configured to obtain heterogeneous SD-WAN environment monitoring data, analyze the connection types of network components based on the heterogeneous SD-WAN environment monitoring data to obtain network component connection type data; and perform heterogeneous SD-WAN network topology structure modeling based on the network component connection type data to obtain a network topology structure model;

[0186] A traffic pattern classification module, configured to extract traffic statistical features from the heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data, analyze traffic behavior patterns based on the traffic statistical data to obtain traffic behavior pattern data; and perform traffic pattern classification marking on the network topology structure model based on the traffic behavior pattern data to obtain a network traffic topology structure model;

[0187] An abnormal behavior correction module, configured to construct a performance benchmark based on the network traffic topology structure model and the heterogeneous SD-WAN environment monitoring data to obtain network performance benchmark data, and perform abnormal behavior correction on the network traffic topology structure model based on the network performance benchmark data to obtain a network traffic corrected topology structure model;

[0188] A multi-dimensional data fusion module, configured to extract network component resource allocation features from the heterogeneous SD-WAN environment monitoring data to obtain network component resource allocation data; and perform multi-dimensional data fusion on the network component resource allocation data through the network traffic corrected topology structure model to obtain a network performance analysis report;

[0189] A resource allocation strategy optimization module, configured to optimize the component resource allocation strategy for the network component resource allocation data based on the network performance analysis report to obtain an optimized network component resource allocation strategy, and upload it to the heterogeneous SD-WAN network management platform to execute the resource allocation optimization task.

[0190] The heterogeneous SD-WAN fusion monitoring system of the present invention can implement any heterogeneous SD-WAN fusion monitoring method of the present invention, and is used as a medium for coordinating the operations and signal transmissions between various modules to complete the heterogeneous SD-WAN fusion monitoring method. The internal modules of the system cooperate with each other to improve the overall network management efficiency.

[0191] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Thus, all changes falling within the meaning and scope of the equivalent elements of the application documents are intended to be embraced within the present invention.

[0192] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. A fusion monitoring method based on heterogeneous SD-WAN, characterized in that: The following steps are involved: Step S1: Obtain heterogeneous SD-WAN environment monitoring data, and perform network component connection type analysis based on the heterogeneous SD-WAN environment monitoring data, thereby obtaining network component connection type data; perform heterogeneous SD-WAN network topology modeling based on the network component connection type data, thereby obtaining a network topology structure model; Step S2: extracting traffic statistical features from heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data, and performing traffic behavior pattern analysis based on the traffic statistical data to obtain traffic behavior pattern data; classifying and marking the network topology structure model based on the traffic behavior pattern data to obtain a network traffic topology structure model; Step S3: constructing a performance benchmark based on the network traffic topology structure model and the heterogeneous SD-WAN environment monitoring data to obtain network performance benchmark data, and performing abnormal behavior correction on the network traffic topology structure model based on the network performance benchmark data to obtain a network traffic correction topology structure model; Step S4: extracting network component resource allocation features from heterogeneous SD-WAN environment monitoring data to obtain network component resource allocation data; Through the network traffic correction topology structure model, multi-dimensional data fusion is performed on the network component resource allocation data to obtain a network performance analysis report; Step S5: Optimize the component resource allocation strategy of the network component resource allocation data based on the network performance analysis report to obtain the optimized network component resource allocation strategy, and upload it to the heterogeneous SD-WAN network management platform to perform the resource allocation optimization task.

2. The heterogeneous SD-WAN fusion monitoring method according to claim 1 is characterized in that: Step S1 is specifically as follows: Step S11: Obtain heterogeneous SD-WAN environment monitoring data, and extract network component connection features from the heterogeneous SD-WAN environment monitoring data, thereby obtaining network component connection data; Step S12: classifying the network component connection data into network component connection types, thereby obtaining network component connection type data; Step S13: integrating the network center component connection relationship according to the network component connection type data, thereby obtaining the center component connection relationship data; Step S14: Perform network communication topology analysis based on the central component connection relationship data to obtain a network topology model.

3. The heterogeneous SD-WAN fusion monitoring method according to claim 2 is characterized in that: Step S12 is specifically as follows: Step S121: performing component connection frequency statistics on the network component connection data, thereby obtaining high-frequency connection component data and low-frequency connection component data; Step S122: selecting the highest frequency connection component according to the high frequency connection component data, thereby obtaining the network center component data; Step S123: performing central component connection frequency statistics on the high-frequency connection component data and the low-frequency connection component data according to the network central component data, thereby obtaining high-frequency central component connection component data and low-frequency central component connection component data; Step S124: extracting component network connection delay features according to the network component connection data, thereby obtaining component network connection delay data; Step S125: classifying network delay components according to the component network connection delay data, thereby obtaining high-delay connection component data and low-delay connection component data; Step S126: performing a connection component intersection operation on the high-frequency center component connection component data and the low-latency connection component data, thereby obtaining normal network connection component data; Performing a connection component intersection operation on the low-frequency center component connection component data and the high-latency connection component data, thereby obtaining temporary network connection component data; Step S127: Component connection merging is performed according to the network center component data, the normal network connection component data and the temporary network connection component data, so as to obtain network component connection type data.

4. The heterogeneous SD-WAN fusion monitoring method according to claim 2 is characterized in that: Step S14 is specifically as follows: Step S141: extracting component routing protocol features from heterogeneous SD-WAN environment monitoring data, thereby obtaining component routing protocol data; Step S142: performing component routing protocol clustering according to the component routing protocol data, thereby obtaining routing protocol clustering component data; Step S143: performing network protocol topology structure analysis according to routing protocol cluster component data and network component connection data, thereby obtaining a network protocol topology structure model; Step S144: Analyze the logical topology structure of the virtual local area network according to the central component connection relationship data, so as to obtain a network logical topology structure model; Step S145: Perform topology mapping on the network protocol topology structure model and the network logic topology structure model, so as to obtain a network topology structure model.

5. The heterogeneous SD-WAN fusion monitoring method according to claim 1 is characterized in that: Step S2 is specifically as follows: Step S21: extracting traffic statistical features from heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data; Step S22: Analyze the traffic behavior pattern of network components according to the traffic statistics data, so as to obtain the traffic behavior pattern data of network components; Step S23: performing similarity evaluation based on the network component traffic behavior pattern data, thereby obtaining traffic behavior pattern similarity data; Step S24: clustering the network component traffic behavior pattern data according to the traffic behavior pattern similarity data, thereby obtaining traffic behavior pattern data; Step S25: marking the network component traffic behavior patterns of the network topology structure model according to the traffic behavior pattern data, thereby obtaining a network traffic topology structure model.

6. The heterogeneous SD-WAN fusion monitoring method according to claim 5 is characterized in that: Step S22 is specifically as follows: Step S221: extracting network component traffic fluctuation characteristics from traffic statistical data, thereby obtaining network component traffic fluctuation data; Step S222: Calculate the network component traffic benchmark based on the network component traffic fluctuation data, thereby obtaining the network component traffic benchmark data; Step S223: dividing the network component traffic fluctuation data into traffic fluctuation stages according to the network component traffic benchmark data, thereby obtaining network component traffic fluctuation stage division data; Step S224: performing traffic fluctuation periodicity statistics according to the network component traffic fluctuation data, thereby obtaining the network component traffic fluctuation periodicity data; Step S225: Perform traffic behavior pattern recognition and integration based on the network component traffic fluctuation phase division data and the network component traffic fluctuation periodicity data, so as to obtain the network component traffic behavior pattern data.

7. The heterogeneous SD-WAN fusion monitoring method according to claim 1 is characterized in that: Step S3 is specifically as follows: Step S31: extracting network transmission features from heterogeneous SD-WAN environment monitoring data to obtain network transmission data, and calculating network component transmission packet loss rate from the network transmission data to obtain component transmission packet loss rate data; Step S32: Calculate the component network link traffic jitter on the network traffic topology structure model, thereby obtaining component network link traffic jitter data; Step S33: performing traffic jitter benchmark statistics on the component network link traffic jitter data, thereby obtaining traffic jitter benchmark data; Perform transmission packet loss rate benchmark statistics on component transmission packet loss rate data, thereby obtaining transmission packet loss rate benchmark data; Step S34: constructing a weighted average benchmark according to the traffic jitter benchmark data and the transmission packet loss rate benchmark data, thereby obtaining network performance benchmark data; Step S35: Correct the abnormal behavior of the network traffic topology structure model according to the network performance benchmark data, so as to obtain a network traffic corrected topology structure model.

8. The heterogeneous SD-WAN fusion monitoring method according to claim 7 is characterized in that: Step S35 is specifically as follows: Step S351: classifying the traffic behavior pattern data into abnormal traffic behavior patterns according to the network performance benchmark data, thereby obtaining abnormal traffic behavior pattern data; Step S352: Calculating the reference error of the abnormal traffic behavior pattern data, thereby obtaining the abnormal traffic behavior pattern reference error data; Step S353: performing low-amount benchmark error statistical analysis on the abnormal traffic behavior pattern benchmark error data, thereby obtaining low-amount benchmark error pattern data; Step S354: removing the low-amount reference error pattern from the abnormal flow behavior pattern data according to the low-amount reference error pattern data, thereby obtaining abnormal flow behavior pattern correction data; Step S355: remove abnormal traffic behavior pattern marks of network components from the network traffic topology structure model according to the abnormal traffic behavior pattern correction data, thereby obtaining a network traffic correction topology structure model.

9. The heterogeneous SD-WAN fusion monitoring method according to claim 1 is characterized in that: Step S4 is specifically as follows: Step S41: extracting network component resource allocation features from heterogeneous SD-WAN environment monitoring data, thereby obtaining network component resource allocation data; Step S42: integrating the traffic behavior pattern of the network traffic correction topology structure model, thereby obtaining traffic behavior pattern correction data; Step S43: fusing the traffic behavior pattern correction data and the network component resource allocation data in the time and space traffic dimension through the network traffic correction topology structure model, thereby obtaining a time and space traffic dimension fusion model; Step S44: Perform network component network performance evaluation according to the spatiotemporal traffic dimension fusion model, thereby obtaining network component network performance evaluation data; Step S45: Visualize the traffic-resource utilization timing correlation based on the network component network performance evaluation data, so as to obtain a network performance analysis report.

10. A heterogeneous SD-WAN fusion monitoring system, characterized in that: Used to execute a heterogeneous SD-WAN fusion monitoring method according to claim 1, the heterogeneous SD-WAN fusion monitoring system comprises: The network topology modeling module is used to obtain heterogeneous SD-WAN environment monitoring data, and perform network component connection type analysis based on the heterogeneous SD-WAN environment monitoring data, thereby obtaining network component connection type data; perform heterogeneous SD-WAN network topology modeling based on the network component connection type data, thereby obtaining a network topology model; The traffic pattern classification module is used to extract traffic statistical features from heterogeneous SD-WAN environment monitoring data to obtain traffic statistical data, and to analyze traffic behavior patterns based on the traffic statistical data to obtain traffic behavior pattern data; traffic pattern classification and labeling of the network topology model based on the traffic behavior pattern data to obtain a network traffic topology model; An abnormal behavior correction module is used to construct a performance benchmark based on a network traffic topology structure model and heterogeneous SD-WAN environment monitoring data, thereby obtaining network performance benchmark data, and to perform abnormal behavior correction on the network traffic topology structure model based on the network performance benchmark data, thereby obtaining a network traffic correction topology structure model; The multi-dimensional data fusion module is used to extract the network component resource allocation features from the heterogeneous SD-WAN environment monitoring data, thereby obtaining the network component resource allocation data; the network component resource allocation data is multi-dimensionally fused through the network traffic correction topology structure model, thereby obtaining a network performance analysis report; The resource allocation strategy optimization module is used to optimize the component resource allocation strategy of the network component resource allocation data based on the network performance analysis report, so as to obtain the optimized network component resource allocation strategy and upload it to the heterogeneous SD-WAN network management platform to perform resource allocation optimization tasks.

Citation Information

Patent Citations

  • Flow generator virtualization realization system and flow generator virtualization realization method based on SDN

    CN105915407A

  • Network flow monitoring system

    CN117896163A